French NATIONAL DIGITAL SECURITY STRATEGY — INTRODUCTION
of attack and the development of organised crime in
cyberspace.
But another type of challenge has arisen; that posed
by the appropriation of digital wealth by a business
oligopoly using their dominant position to interfere
with the arrival of new businesses and to harness the
added value of this budding economy, which will exploit data intended to invent new services, improve our
daily lives or make public services more accessible. At
the forefront of these data is our personal data; including those related to our privacy. Control of this mass
of data opens the way to economic destabilisation
and to sophisticated forms of propaganda or ways to
mislead people’s judgments and habits. In this respect,
this threat is a matter for national defence and security,
because of its national extent and strategic issues.
tiated by the State’s services.
The ministries have become aware of the political
and technical impact of information technologies on
their missions and administration activity and are becoming equipped with coordinators in charge of digital
issues and the security aspects thereof. A State Information Systems Security Policy was developed and is
progressively being implemented.
In the coming years it should be possible to reap
the benefits of the measures taken and to extend the
scope of public action and stakeholders. It must now be
acknowledged and made known that the defence and
security of digital technology depends on the national
community and not only on the action of the State.
*
*
*
*
*
*
In light of these risks, which unfortunately are
already established, much has already been accomplished.
As was announced in the 2008 French White Paper
on Defence and National Security, a national agency
was created as of 2009 to address cyberattacks and to
protect the State information systems and critical infrastructures.
An industrial policy in favour of the national cybersecurity industry is notably supported by the future
investments programme and in the framework of the
«Future industry» plan.
In 2013 the French Parliament voted for the measures recommended by the Government aimed at reinforcing the cybersecurity of operators of vital importance and of those who participate in their most critical
information systems.
France’s positions are supported within all international bodies, and notably the United Nations (UN)
which acknowledged the application of international
law to cyberspace in 2013. In addition, bilateral operational relations with several countries have been ini-
8
Up until the past few years, our defence and national security depended on the expertise, behaviour and
decisions of men and women with access to the most
sophisticated, protected and secret installations and
equipment. But with the emergence of a society that
is massively connected, this responsibility is now partially shared by all French people. One connected object or one service that is inadequately secured by its
developers, negligence by one information systems’ security decision-maker, dangerous behaviour by one service provider or by one employee who carelessly mixes
private life and professional life can lead to losses in
availability, confidentiality or integrity of essential information, suspensions in activity and economic losses,
industrial accidents and losses of human lives or ecological catastrophes and disturbances in public order,
capable of affecting the life of the entire nation.
In fact, never has the stability of our future, supported by digital technology, been so dependent on
each person’s responsibilities and on the collective responsibilities of three communities of stakeholders.
The first community is responsible for recommending and implementing technologies, products and services equipped with the level of security that is adap-